CVE Database
/

CVE-2022-40700

Back to search

CVE-2022-40700

Published: Jan 19, 2024

Modified: Apr 28, 2026

PUBLISHED

CVSS v3.1

8.2

HIGH

Description

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.

VendorProductVersions

Montonio

Montonio for WooCommerce

affected
n/a - <= 6.0.1

Wpopal

Wpopal Core Features

affected
n/a - <= 1.5.8

AMO for WP – Membership Management

ArcStone

affected
n/a - <= 4.6.6

Long Watch Studio

WooVirtualWallet – A virtual wallet for WooCommerce

affected
n/a - <= 2.2.1

Long Watch Studio

WooVIP – Membership plugin for WordPress and WooCommerce

affected
n/a - <= 1.4.4

Long Watch Studio

WooSupply – Suppliers, Supply Orders and Stock Management

affected
n/a - <= 1.2.2

Squidesma

Theme Minifier

affected
n/a - <= 2.0

Paul Clark

Styles

affected
n/a - <= 1.2.3

Designmodo Inc.

WordPress Page Builder – Qards

affected
n/a - <= 1.0.5

Philip M. Hofer (Frumph)

PHPFreeChat

affected
n/a - <= 0.2.8

Arun Basil Lal

Custom Login Admin Front-end CSS

affected
n/a - <= 1.4.1

Team Agence-Press

CSS Adder By Agence-Press

affected
n/a - <= 1.5.0

Unihost

Confirm Data

affected
n/a - <= 1.0.7

deano1987

AMP Toolbox

affected
n/a - <= 2.1.1

Arun Basil Lal

Admin CSS MU

affected
n/a - <= 2.6

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

Low

Availability

None

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now